
CVE-2025-5781
Proof-of-concept exploit for CVE-2025-57819 in FreePBX: SQL injection in the AJAX API to execute arbitrary PHP, create a persistent webshell, and…

Proof-of-concept exploit for CVE-2025-57819 in FreePBX: SQL injection in the AJAX API to execute arbitrary PHP, create a persistent webshell, and…

Remote code execution vulnerability in OpenEMR <8.0.0.2.

[CVE-2021-22123] Fortinet FortiWeb Authenticated OS Command Injection

A standalone Rust implementation of the CVE-2007-2447 exploit targeting Samba smbd 3.0.20-Debian.

PoC for achieving RCE in Langflow versions <1.3.0

CVE-2022-31814 Exploitation Toolkit.

Remote OS Command Injection in TastyIgniter v3.0.7 Sendmail Path field

MAL-004: Command Injection Bypass for CVE-2020-12641 in Roundcube Webmail

Evince/xreader/Atril RCE exploit to CVE-2026-46529

PoC for CVE-2026-46420, command injection in shivammathur/setup-php via repository-controlled PHP version resolution.

CVE-2025-69212 - OpenSTAManager has an OS Command Injection in P7M File Processing


CVE-2024-41997 PoC - accompanies https://0day.gg/blog/warp-terminal-rce/


Python script for exploiting command injection in Open PLC Webserver v3

Remote authentication bypass exploit for GNU inetutils-telnetd (CVE-2026-24061) using CRLF injection to gain instant root shell. Supports single/mass…

CVE-2026-6279: Avada (Fusion) Builder <= 3.15.2 – Unauthenticated Remote Code Execution via PHP Function Injection via 'render_logics' Shortcode…

PoC exploit for CVE-2020-11800, a command injection in Zabbix Server via malicious agent auto-registration, with Python-based payload delivery and…